First published: Thu Apr 08 2021(Updated: )
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpodofo | <=0.9.7+dfsg-2<=0.9.8+dfsg-3<=0.9.8+dfsg-3.2 | |
PoDoFo | =0.9.7 | |
Red Hat Enterprise Linux | =7.0 | |
Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30471 has a severity level that may lead to significant operational impacts due to the potential for stack overflow.
To address CVE-2021-30471, update PoDoFo to a version above 0.9.7 or apply relevant security patches provided by the distribution.
CVE-2021-30471 affects PoDoFo versions 0.9.7 as well as specific packages such as libpodofo on Debian and Fedora systems.
CVE-2021-30471 is characterized by an uncontrolled recursive call causing a stack overflow in the PdfNamesTree::AddToDictionary function.
While CVE-2021-30471 primarily results in a stack overflow, it does not directly indicate the potential for remote code execution.